İçeriğe atla
Noroxi

CWE-73 · 573 kayıt

External Control of File Name or Path

Bu sınıftaki CVE’ler

574 kayıt

  • Internet Shortcut Files Remote Code Execution Vulnerability

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %87

    microsoft · windows 10 150710 Haz 2025

  • NTLM Hash Disclosure Spoofing Vulnerability

    OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %84

    microsoft · windows 10 150712 Kas 2024

  • CVE-2022-39952
    69Bu hafta

    A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,

    KritikCVSS 9,8SilahlaştırılmışEPSS %100

    fortinet · fortinac16 Şub 2023

  • CVE-2025-24054
    69Bu hafta

    NTLM Hash Disclosure Spoofing Vulnerability

    OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %59

    microsoft · windows 10 150711 Mar 2025

  • CVE-2024-8517
    67Bu hafta

    SPIP Bigup Multipart File Upload OS Command Injection

    KritikCVSS 9,8SilahlaştırılmışEPSS %95

    spip · spip6 Eyl 2024

  • CVE-2023-4634
    65Bu hafta

    Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution

    KritikCVSS 9,8Kavram kanıtıEPSS %86

    davidlingren · media library assistant6 Eyl 2023

  • CVE-2018-17246
    64Bu hafta

    Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.

    KritikCVSS 9,8Kavram kanıtıEPSS %82

    elastic · kibana20 Ara 2018

  • CVE-2023-3643
    62Bu hafta

    Boss Mini document file inclusion

    KritikCVSS 9,8Kavram kanıtıEPSS %75

    carel · boss mini firmware12 Tem 2023

  • CVE-2025-0111
    59Planlayın

    PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface

    YüksekCVSS 7,1KEVSilahlaştırılmışEPSS %2

    paloaltonetworks · pan-os12 Şub 2025

  • CVE-2021-27250
    46Planlayın

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 v1.01rc0

    OrtaCVSS 6,5İstismar yokEPSS %67

    dlink · dap-2020 firmware14 Nis 2021

  • CVE-2021-21343
    44Planlayın

    XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights

    YüksekCVSS 7,5İstismar yokEPSS %47

    xstream · xstream22 Mar 2021

  • CVE-2024-37149
    41Planlayın

    GLPI allows remote code execution through the plugin loader

    YüksekCVSS 8,8İstismar yokEPSS %21

    glpi-project · glpi10 Tem 2024

  • CVE-2024-0265
    41Planlayın

    SourceCodester Clinic Queuing System GET Parameter index.php file inclusion

    YüksekCVSS 8,8İstismar yokEPSS %21

    oretnom23 · clinic queuing system7 Oca 2024

  • CVE-2024-0087
    41Planlayın

    NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.

    YüksekCVSS 8,8İstismar yokEPSS %20

    nvidia · triton inference server14 May 2024

  • CVE-2025-71338
    40Planlayın

    Flowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-store API

    KritikCVSS 10,0Kavram kanıtıEPSS %1

    flowiseai · flowise25 Haz 2026

  • CVE-2025-54945
    40Planlayın

    SUNNET Corporate Training Management System - External Control of File Name or Path

    KritikCVSS 10,0İstismar yokEPSS %1

    sun.net · ehrd ctms30 Ağu 2025

  • CVE-2026-20358
    40Planlayın

    Cisco Crosswork Security Hardening Release: August 2026

    KritikCVSS 10,0İstismar yokEPSS %0

    cisco · cisco crosswork planning19 Ağu 2026

  • CVE-2025-6463
    39İzleyin

    Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submiss

    YüksekCVSS 8,8İstismar yokEPSS %13

    incsub · forminator2 Tem 2025

  • CVE-2019-3681
    39İzleyin

    osc: stores downloaded (supposed) RPM in network-controlled filesystem paths

    KritikCVSS 9,8İstismar yokEPSS %1

    suse · linux enterprise server29 Haz 2020

  • CVE-2026-11526
    39İzleyin

    GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle

    KritikCVSS 9,8İstismar yokEPSS %1

    rurban · gd14 Haz 2026

  • CVE-2023-2152
    39İzleyin

    SourceCodester Student Study Center Desk Management System index.php file inclusion

    KritikCVSS 9,8İstismar yokEPSS %1

    oretnom23 · student study center desk management system18 Nis 2023

  • CVE-2021-38477
    39İzleyin

    There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipul

    KritikCVSS 9,8İstismar yokEPSS %1

    auvesy · versiondog22 Eki 2021

  • CVE-2020-9752
    39İzleyin

    Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through i

    KritikCVSS 9,8İstismar yokEPSS %1

    naver · cloud explorer22 Mar 2020

  • CVE-2023-47862
    39İzleyin

    A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb.

    KritikCVSS 9,8İstismar yokEPSS %1

    wwbn · avideo10 Oca 2024

  • CVE-2023-4749
    39İzleyin

    SourceCodester Inventory Management System index.php file inclusion

    KritikCVSS 9,8İstismar yokEPSS %1

    mayurik · inventory management system3 Eyl 2023

Tüm zafiyet sınıfları